Inbound web command-execution attempt detected and blocked by perimeter IDS/IPS.
Observed 1 blocked ...
show moreInbound web command-execution attempt detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/IPS event.
Observed IDS/IPS evidence:
- ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt
Target service: HTTP / TCP port 80
Severity: 9/10
First seen: 2026-10-05T20:54:17.106Z
Last seen: 2026-10-05T20:54:17.106Z
Reference: STI-20261005-225417-144-225-6-184
show less
Git repository probing detected against a public web server.
37 suspicious requests
37 critical req ...
show moreGit repository probing detected against a public web server.
37 suspicious requests
37 critical requests
Observed requests:
GET /web/.env
GET /site/.env
GET /.git/config
Risk level: HIGH
Reference: STI-20261005-182510-35-211-253-95
show less
Inbound web exploitation attempt detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/ ...
show moreInbound web exploitation attempt detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/IPS event.
Observed IDS/IPS evidence:
- ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2
Target service: HTTP / TCP port 80
Severity: 9/10
First seen: 2026-10-05T10:54:22.697Z
Last seen: 2026-10-05T10:54:22.697Z
Reference: STI-20261005-125422-162-35-120-21
show less
Git repository probing detected against a public web server.
20 suspicious requests
20 critical req ...
show moreGit repository probing detected against a public web server.
20 suspicious requests
20 critical requests
Observed requests:
GET /.git/config
GET /.env.test
GET /.env.staging
Risk level: HIGH
Reference: STI-20261005-092457-35-213-254-0
show less
Git repository probing detected against a public web server.
74 suspicious requests
74 critical req ...
show moreGit repository probing detected against a public web server.
74 suspicious requests
74 critical requests
Observed requests:
GET /web/.env
GET /site/.env
GET /.git/config
Risk level: HIGH
Reference: STI-20261005-085445-35-214-41-76
show less
WordPress exploitation attempts detected against a public web server.
78 suspicious requests
59 cri ...
show moreWordPress exploitation attempts detected against a public web server.
78 suspicious requests
59 critical requests
Observed requests:
GET /wp-content/debug.log
GET /wp-config.php.bak
GET /web/.env
GET /vendor/composer/installed.json
GET /v2/.env
Risk level: CRITICAL
Reference: STI-20261005-085446-35-241-239-86
show less
Automated web application probing detected against a public web server.
2 suspicious requests
2 cri ...
show moreAutomated web application probing detected against a public web server.
2 suspicious requests
2 critical requests
Observed requests:
GET /zwso.php
GET /yachi.php
GET /xivoefjr.php
GET /xcrarnkpo.php
GET /wpxml.php
Risk level: VERY_HIGH
Reference: STI-20261005-045431-20-197-26-46
show less
Sensitive file and configuration probing detected against a public web server.
125 suspicious reque ...
show moreSensitive file and configuration probing detected against a public web server.
125 suspicious requests
125 critical requests
Observed requests:
GET /www/.env
GET /web/.env
GET /var/www/html/.env
GET /var/www/.env
Risk level: VERY_HIGH
Reference: STI-20261005-035428-34-69-36-150
show less
WordPress exploitation attempts detected against a public web server.
57 suspicious requests
46 cri ...
show moreWordPress exploitation attempts detected against a public web server.
57 suspicious requests
46 critical requests
Observed requests:
GET /.yarnrc.yml
GET /wp-config.php.save
GET /wp-config.php.old
GET /wp-config.php~
GET /wp-config.php
Risk level: CRITICAL
Reference: STI-20261005-025420-54-207-116-2
show less
Automated web application probing detected against a public web server.
4 suspicious requests
2 cri ...
show moreAutomated web application probing detected against a public web server.
4 suspicious requests
2 critical requests
Observed requests:
GET /yich.php
GET /x.php
GET /wp-log.php
GET /wp-filemanager1_260805194013.php
GET /wp-fgban13jx3.php
Risk level: VERY_HIGH
Reference: STI-20261004-102450-20-219-185-206
show less
Automated web application probing detected against a public web server.
4 suspicious requests
2 cri ...
show moreAutomated web application probing detected against a public web server.
4 suspicious requests
2 critical requests
Observed requests:
GET /yich.php
GET /x.php
GET /wp-log.php
GET /wp-filemanager1_260805194013.php
GET /wp-fgban13jx3.php
Risk level: VERY_HIGH
Reference: STI-20261004-042421-13-70-107-184
show less
Automated web application probing detected against a public web server.
12 suspicious requests
3 cr ...
show moreAutomated web application probing detected against a public web server.
12 suspicious requests
3 critical requests
Observed requests:
GET /zero.php
GET /yich.php
GET /x.php
GET /wp-log.php
GET /wp-logis.php
Risk level: CRITICAL
Reference: STI-20261004-015423-20-210-186-186
show less
Automated web application probing detected against a public web server.
19 suspicious requests
11 c ...
show moreAutomated web application probing detected against a public web server.
19 suspicious requests
11 critical requests
Observed requests:
GET /ps-18daf6432b467294-1d7990-notfound
GET /_profiler/phpinfo
GET /phpinfo.php
GET /php_info.php
GET /phpinfo
Risk level: CRITICAL
Reference: STI-20261003-105419-45-138-12-53
show less
Git repository probing detected against a public web server.
22 suspicious requests
16 critical req ...
show moreGit repository probing detected against a public web server.
22 suspicious requests
16 critical requests
Observed requests:
GET /wp-config.php
GET /wp-config.php.bak
GET /.git/refs/heads/master
GET /.git/refs/heads/main
GET /.git/logs/HEAD
Risk level: HIGH
Reference: STI-20261003-035359-35-231-52-75
show less
Inbound malicious web activity detected and blocked by perimeter IDS/IPS.
Observed 10 blocked IDS/I ...
show moreInbound malicious web activity detected and blocked by perimeter IDS/IPS.
Observed 10 blocked IDS/IPS events.
Observed IDS/IPS evidence:
- ET USER_AGENTS Suspcious LeakIX User-Agent (l9explore)
Target service: HTTP/HTTPS / TCP port 80,443
Severity: 7/10
First seen: 2026-09-01T20:06:57.184Z
Last seen: 2026-10-02T15:16:24.261Z
Reference: STI-20261002-171624-193-32-204-199
show less
Sensitive file and configuration probing detected against a public web server.
27 suspicious reques ...
show moreSensitive file and configuration probing detected against a public web server.
27 suspicious requests
27 critical requests
Observed requests:
GET /.env.test
GET /.env.template
GET /.env.staging
GET /.env.sample
GET /.env.production
Risk level: CRITICAL
Reference: STI-20261002-165409-209-99-188-251
show less
Sensitive file and configuration probing detected against a public web server.
40 suspicious reques ...
show moreSensitive file and configuration probing detected against a public web server.
40 suspicious requests
14 critical requests
Observed requests:
GET /.env
POST /login
POST /api
Risk level: CRITICAL
Reference: STI-20261002-112355-31-59-160-3
show less
WordPress exploitation attempts detected against a public web server.
24 suspicious requests
8 crit ...
show moreWordPress exploitation attempts detected against a public web server.
24 suspicious requests
8 critical requests
Observed requests:
GET /assets/index-BiJ2MzwC.js HTTP/2.0
GET /wp-content/debug.log HTTP/2.0
GET /wp-config.php.bak HTTP/2.0
GET /web.config HTTP/2.0
GET /vendor/composer/installed.json HTTP/2.0
Risk level: CRITICAL
Reference: STI-20261002-085037-45-138-12-25
show less
Inbound malicious web activity detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/IP ...
show moreInbound malicious web activity detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/IPS event.
Observed IDS/IPS evidence:
- ET WEB_SERVER Possible SQL Injection SELECT CONCAT in HTTP Request Body
Target service: HTTP / TCP port 80
Severity: 9/10
First seen: 2026-10-02T04:31:55.946Z
Last seen: 2026-10-02T04:31:55.946Z
Reference: STI-20261002-063155-178-62-234-41
show less
WordPress exploitation attempts detected against a public web server.
26 suspicious requests
20 cri ...
show moreWordPress exploitation attempts detected against a public web server.
26 suspicious requests
20 critical requests
Observed requests:
GET /wp-content/mysql.sql
GET /wp-config.php.backup
GET /WEB-INF/web.xml
GET /test/
GET /system/.env
Risk level: CRITICAL
Reference: STI-20261002-064919-185-218-86-26
show less
Inbound web exploitation attempt detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/ ...
show moreInbound web exploitation attempt detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/IPS event.
Observed IDS/IPS evidence:
- ET WEB_SPECIFIC_APPS React Server Components React2Shell Unsafe Flight Protocol Property Access (CVE-2025-55182)
Target service: HTTP / TCP port 80
Severity: 9/10
First seen: 2026-10-02T02:42:26.052Z
Last seen: 2026-10-02T02:42:26.052Z
Reference: STI-20261002-044226-18-192-130-150
show less
WordPress exploitation attempts detected against a public web server.
20 suspicious requests
13 cri ...
show moreWordPress exploitation attempts detected against a public web server.
20 suspicious requests
13 critical requests
Observed requests:
GET /wp-config.php
GET /wp-admin/setup-config.php
GET /_vti_pvt/service.pwd
Risk level: CRITICAL
Reference: STI-20261001-131919-91-148-244-131
show less
WordPress exploitation attempts detected against a public web server.
40 suspicious requests
26 cri ...
show moreWordPress exploitation attempts detected against a public web server.
40 suspicious requests
26 critical requests
Observed requests:
GET /wp-config.php
GET /wp-admin/setup-config.php
GET /_vti_pvt/service.pwd
Risk level: CRITICAL
Reference: STI-20261001-131918-91-148-245-81
show less
Inbound web exploitation attempt detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/ ...
show moreInbound web exploitation attempt detected and blocked by perimeter IDS/IPS.
Observed 1 blocked IDS/IPS event.
Observed IDS/IPS evidence:
- ET EXPLOIT HackingTrio UA (Hello, World)
Target service: HTTP / TCP port 80
Severity: 9/10
First seen: 2026-10-01T10:17:29.323Z
Last seen: 2026-10-01T10:17:29.323Z
Reference: STI-20261001-121729-72-255-19-1
show less
HackingWeb App Attack
By clicking โAccept allโ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.